CVE-2018-17054: XSS
Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17053.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17054?
CVE-2018-17054 is a cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0.
What is the severity of CVE-2018-17054?
The severity of CVE-2018-17054 is medium with a CVSS score of 6.1.
How does CVE-2018-17054 work?
CVE-2018-17054 allows remote attackers to inject arbitrary web script or HTML through vectors related to login request parameters.
Which software versions are affected by CVE-2018-17054?
Progress Sitefinity CMS versions 10.0 through 11.0 are affected by CVE-2018-17054.
How can I fix CVE-2018-17054?
To fix CVE-2018-17054, it is recommended to update to a patched version of Progress Sitefinity CMS.